MSP cybersecurity news digest, April 27, 2026
ID: 7fe5c0a5-f7db-5d64-8a99-306d3acce1f5
STIX ID: report--7fe5c0a5-f7db-5d64-8a99-306d3acce1f5
Feed Name: TRU Security by Acronis
This report summarizes multiple active threats: UNC6692 abused Microsoft Teams and helpdesk impersonation to deliver a Snow malware toolkit (backdoor, tunneler, malicious browser extension); Bitwarden’s CLI npm package was briefly poisoned to harvest developer secrets; OAuth-based phishing is being used to hijack Microsoft 365 via malicious apps; Trigona deployed a custom exfiltration tool ahead of ransomware activity; and ADT experienced a data breach tied to ShinyHunters — collectively highlighting supply-chain risks, token-based persistence, stealthy exfiltration, and identity-focused intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
